6.1 Applicability
This policy applies to all employees, co-founders, interns, contractors, and freelancers ("Personnel") who
have access to Hirfa's internal systems, source code, or confidential information, regardless of employment
classification.
6.2 Confidentiality Obligations
Every member of Personnel must execute a Non-Disclosure Agreement ("NDA") prior to being granted any system
access. The NDA covers:
- Trade secrets: business model details, financial projections, fundraising materials,
and go-to-market/geographic expansion strategy.
- User data: any personal data belonging to Clients or Craftsmen, regardless of data
classification level.
- Source code and architecture: the Platform's codebase, infrastructure design, and
security controls.
- Unreleased product plans: features, pricing changes, or partnerships not yet publicly
announced.
6.3 Duration of Confidentiality
Confidentiality obligations remain in effect for the full duration of the engagement with Hirfa and for a
minimum of three (3) years following termination, regardless of the reason for termination (resignation,
dismissal, or contract expiry).
6.4 Intellectual Property Assignment
All work product — code, designs, documentation, or other creative or technical output — produced by
Personnel in connection with their engagement with Hirfa, or using Hirfa's resources, is deemed work made
for hire and is the exclusive property of HIRFA LLC, except where a separate written agreement explicitly
states otherwise.
6.5 System Access and Offboarding
- Personnel are granted system access strictly according to the Least Privilege principle defined in the
Access Control Policy (Section 8).
- Upon termination of engagement for any reason, all system access, credentials, and physical/company
assets must be revoked and returned on the last day of engagement, following the formal Offboarding
Checklist.
6.6 Acceptable Device and Network Use
- Devices and accounts used to access Hirfa systems must be protected with a strong password/passphrase
and mandatory two-factor authentication.
- Access to production systems over unsecured public Wi-Fi networks is prohibited without an approved VPN
connection.
- Personnel must not store confidential Hirfa data on personal, unmanaged devices or personal cloud
storage accounts.
6.7 Reporting Obligations
Personnel who become aware of a security incident, policy violation, or suspected breach of confidentiality
— by themselves or others — are obligated to report it immediately to security@gethirfa.com,
without fear of retaliation for good-faith reporting.